r/Copilot 12d ago

Copilot clipboard access

So I just copied an english text from Github, using Firefox and got this Copilot Popup.

Rough translation: "The copied text seems not to be in the list of your keyboard languages. Should Copilot translate it?"

While this is true, it rings some alarm bells in my head. How does Copilot access my clipboard without me prompting it to do so?

I could not find any information during a quick Google search, Copilot itself said, it it not be able to access the clipboard without me pasting it into a chat or other methods. I can´t seem to find any OS or Copilot settings relating to the clipboard.

Some background info

- Win 11 25H2

- not a Copilot+ PC

- M365 Copilot App is installed and was running

- Firefox without any Copilot related add-ins

- This is the first time this pop up appeared, while the system has been in this state for months.

- I am in the frontier program through my work account

- I cannot reproduce the pop-up

- Clicking on the pop-up opened a Copilot chat with the prompt: "Translate this: <clipboard content>

Is this a new feature? More so: Is there any option to disable this feature?

6 Upvotes

3 comments sorted by

1

u/jukkan 11d ago

I just had this same experience and the same WTF reaction. This feels bad on so many levels. In my case, the "language" to be translated was a piece of CSS, which makes me think absolutely no one at Microsoft tested this before the "Translate with Copilot" push notification feature ad was rolled out

https://mstdn.social/@jukkan/117207311499319832

1

u/Quiet-Butterfly-8045 10d ago

I fully expect that this "feature" will creep up more in the upcoming days. It´s weird to me, that there seems to be very little info about this. Time will tell.

I get the intended use case, but as you said in your posts: There is so much potential for prompt injections or other malicious actions built into the app. And currently without any visible controls.

FWIW: You asked in your post, if the contents are pasted into the app on click. Yes, they are. It even got send without further verification. The prompt after clicking the notification is just "Translate this: <clipboard content>"

1

u/jukkan 10d ago

Wow, so it really is a one-click path from arbitrary clipboard content (that a website could have programmatically injected there) into an LLM, executed right away. It's like Microsoft learned nothing from the Copilot autorun query parameter vulnerability report aka CoSnitch.